Legal
GDPR in the salon: what is actually required
Data protection sounds like bureaucracy but is manageable in a salon once you know the basics. This text is not legal advice but gives orientation.
Which data you actually process:
Name, contact details, appointments, treatment notes, and in beauty also health information (allergies, medication). The latter counts as especially sensitive and needs explicit consent.
Consent means active and freely given:
A pre-ticked box is not enough. Newsletters need genuine opt-in, ideally with a confirmation email (double opt-in). For before-and-after photos on Instagram you need separate written consent – the treatment itself does not cover it.
Storing and deleting:
Data is kept as long as it is needed or legal retention periods require (invoices: ten years). After that it is deleted. Clients have the right to request information and demand erasure.
In practice:
A record of processing activities, a privacy policy on the website, contracts with providers who process data for you (booking software, newsletter tools), and lockable cabinets for paper files. That is the core.
Remember:
The most common mistake is not missing paperwork but the Instagram photo without consent. Ask – in writing, once, kindly.
Ready to make your business visible?
Start free